CVE-2019-0541highunder attackCWE-77

CVE-2019-0541: high-severity vulnerability in Microsoft Office

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 53%
from disclosure to weapon64 days
Published on NVDJan 8
1st PoC+64d
CISA KEV+1030d
exploitation probability
53%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

A flaw in Microsoft's web rendering engine (MSHTML) allows attackers to execute malicious code on your computer when you open a specially crafted document or visit a malicious website. This affects multiple Microsoft products including Office, Excel, Word, and Internet Explorer.

Technical detail

MSHTML engine fails to properly validate input in web content, enabling remote code execution via crafted documents or web pages. Attack vector is network-based with low attack complexity; requires user interaction (opening document or visiting site). Successful exploitation grants arbitrary code execution in the context of the affected application.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.